openclaw-rl-training

Warn

Audited by Socket on May 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill broadly matches its stated RL-training purpose, but its footprint is high-risk. The main concerns are autonomous terminal/GUI action execution, interception of live conversations for training, and moderately weak install trust from a GitHub-cloned ML stack with unpinned dependencies. This looks more like a dangerous agent-training capability than overt malware.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
May 16, 2026, 05:51 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fhermes-skills%2Fopenclaw-rl-training%2F@5ba971eebecdfeb3cd1b5f8b9a8be65c91d6471b
Security Audit — socket — openclaw-rl-training